Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

As a Gitcoin operator, I want to patch up security issues related to uploading. #4432

Closed
1 task
frankchen07 opened this issue May 17, 2019 · 2 comments
Closed
1 task
Assignees
Labels
enhancement This is a feature to be enhanced or improved. Gitcoin.co Gitcoin.co site

Comments

@frankchen07
Copy link
Contributor

User Story

As a Gitcoin operator, I want to patch up security issues related to uploading.

Why Is this Needed

Unrestricted file uploads are a security risk.

Current Behavior

Unrestricted file uploads

Expected Behavior

Restricted file uploads using libmagic

Definition of Done

  • restricted file uploads
@frankchen07 frankchen07 added enhancement This is a feature to be enhanced or improved. Gitcoin.co Gitcoin.co site 3 labels May 17, 2019
@kuhnchris
Copy link
Contributor

Uh, differently asked: where the F are files uploaded and reused? Avatar? CV?

@frankchen07
Copy link
Contributor Author

@kuhnchris - this ticket was deliberately left vague as to not explicitly let the public know of the vulnerability itself (maybe overly cautious, but better safe than sorry). It's a core ticket that has been brought to @danlipert - feel free to reach out to him directly on Slack if you'd like to the lowdown!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement This is a feature to be enhanced or improved. Gitcoin.co Gitcoin.co site
Projects
None yet
Development

No branches or pull requests

4 participants